[BUG] RASDepth=1 creates invalid slices in ras.sv #3587
Copy link
Copy link
Open
Labels
Component:RTLFor issues in the RTL (e.g. for files in the rtl directory)For issues in the RTL (e.g. for files in the rtl directory)Status:NewNewly created issue, nobody has looked at it yet.Newly created issue, nobody has looked at it yet.Type:BugFor bugs in the RTL, Documentation, Verification environment or Tool and Build systemFor bugs in the RTL, Documentation, Verification environment or Tool and Build systemnotCV32A65XIt is not an CV32A65X issueIt is not an CV32A65X issue
Description
Activity
- addedType:BugFor bugs in the RTL, Documentation, Verification environment or Tool and Build systemFor bugs in the RTL, Documentation, Verification environment or Tool and Build system
on Sep 23, 2026 - addedComponent:RTLFor issues in the RTL (e.g. for files in the rtl directory)For issues in the RTL (e.g. for files in the rtl directory)Status:NewNewly created issue, nobody has looked at it yet.Newly created issue, nobody has looked at it yet.notCV32A65XIt is not an CV32A65X issueIt is not an CV32A65X issue
on Sep 23, 2026 Thanks for the report, I had already encountered this issue but I did not give it too much attention.
I'm wondering if replacing
stack_d[DEPTH-1:1] = stack_q[DEPTH-2:0]by aforloop would avoid addingDEPTH==1case-specific code?
Metadata
Metadata
Assignees
Labels
Component:RTLFor issues in the RTL (e.g. for files in the rtl directory)For issues in the RTL (e.g. for files in the rtl directory)Status:NewNewly created issue, nobody has looked at it yet.Newly created issue, nobody has looked at it yet.Type:BugFor bugs in the RTL, Documentation, Verification environment or Tool and Build systemFor bugs in the RTL, Documentation, Verification environment or Tool and Build systemnotCV32A65XIt is not an CV32A65X issueIt is not an CV32A65X issue
Code of Conduct
CVA6 commit affected
6cb2001
Bug Description
Bug Description
RASDepthis a public configuration parameter, andconfig_pkg::check_cfgaccepts every value greater than zero. However, settingRASDepth=1makes the production RAS shift logic form the invalid ranges[0:1]and[-1:0], preventing RTL generation. I think this is a CVA6 parameter/RTL consistency issue rather than a RISC-V ISA violation. RISC-V defines call/return hints that an implementation may use for return-address prediction, but it does not require a particular RAS depth.Steps to reproduce
I have provided the reproduction scripts in test.zip.
test/cva6_ras_depth_tb.svinstantiates the production RAS, callsconfig_pkg::check_cfg, and checks a push/pop operation for the control configuration.test/run.shruns the depth-two control and verifies the depth-one compile-time failure against the production source.To reproduce the issue, execute the following steps:
testdirectory next to this issue draft.bash test/run.sh.The test instantiates the production
core/frontend/ras.svwith a minimal configuration derived throughcva6_cfg_t. It first compiles and simulatesDEPTH=2, including a push/pop check, and then compiles the otherwise identicalDEPTH=1trigger.The relevant output is:
Expected behavior
A one-entry RAS accepted by
check_cfgshould compile and support one push/pop entry. If the implementation intentionally requires at least two entries,check_cfgand the parameter documentation should reject one with a clear RAS-specific diagnostic.Observed behavior
The two-entry control compiles, runs, and passes the push/pop check. With one entry, Verilator reports invalid and out-of-range selections in
ras.svand cannot produce the executable model. The error occurs before an instruction-level test can run.Root cause analysis
The push path always executes
stack_d[DEPTH-1:1] = stack_q[DEPTH-2:0], while the pop path always executesstack_d[DEPTH-2:0] = stack_q[DEPTH-1:1]. These are valid for depths of at least two but become[0:1]and[-1:0]whenDEPTH=1. There is no one-entry special case, whilecheck_cfgonly assertsCfg.RASDepth > 0.The relevant source is
core/frontend/ras.svaround lines 45–57 andcore/include/config_pkg.svaround lines 464–469. The design manual also describes the RAS as a LIFO composed ofRASDepthentries without documenting a minimum of two.Reproduction test case
test/cva6_ras_depth_tb.svinstantiates the production RAS, callsconfig_pkg::check_cfg, and checks a push/pop operation for the control configuration.test/run.shruns the depth-two control and verifies the depth-one compile-time failure against the production source.Possible fixes
The preferable fix is to special-case
DEPTH==1so push writes entry zero and pop invalidates entry zero without evaluating empty shift slices. The smaller alternative is to change the configuration check to requireRASDepth > 1and document that restriction. A regression should cover the minimum accepted nonzero depth.Environment and source
6cb200105fb9441d170e45786125a737fab98e91.core/frontend/ras.sv.core/include/config_pkg.sv.